September 9, 2026AgentsMonitoring

Infostealers Found a New Prize: Your Claude Session

Anthropic confirmed this week that a wave of infostealer malware is hijacking Claude subscriber accounts - and the loot isn't your credit card, it's your usage quota. Vidar, LummaC2, StealC, RedLine and Acreed on Windows, Atomic Stealer on macOS: all now grab Claude session cookies and tokens, which walk straight past MFA because the session is already authenticated.

TechCrunch's named case makes it concrete: consultant Grant de Swardt, paying for the Max 20x plan, found his account burning through usage he never touched back in August. Attackers either resell access to the hijacked session or run their own agent workloads on the victim's meter. Anthropic's response: forced sign-outs, invalidated authorizations, removal of saved payment methods, and refunds for unauthorized charges.

Step back and this is a genuinely new economic-crime primitive. A Max subscription is a claim on frontier compute, resets-wars pricing made that claim scarce, and scarce claims get stolen. Stolen streaming logins sold for a couple of dollars; a 20x coding-agent quota is worth real money to anyone running agents at scale who'd rather not pay. The security perimeter of the agent era isn't just your API keys - it's every browser cookie that can drive a model.

Coverage: https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers/ and https://www.malwarebytes.com/blog/news/2026/09/infostealers-are-hijacking-claude-accounts-at-users-expense
← Previous
Meta Muse: The First Hyperscaler Agent That Spends Your Money
Next β†’
Mercury 2.5: The Diffusion Bet on the Agent Loop
← Back to all articles

Comments

Loading...
>_